CVE-2022-25647
01.05.2022, 16:15
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gson | 2.2.3 ≤ 𝑥 < 2.8.9 | |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
| oracle | graalvm | 20.3.6 |
| oracle | graalvm | 21.3.2 |
| oracle | graalvm | 22.1.0 |
| oracle | retail_order_broker | 18.0 |
| oracle | retail_order_broker | 19.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References